7.5
    High

    CVE-2009-4650

    Last Modified: 4 Jun 2014

    SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. NOTE: some of these details are obtained from third party information.

    Source:Jeff Channell
    Published:22 Feb 2010
    7.2
    High

    CVE-2009-4648

    Last Modified: 28 Mar 2019

    Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --file_move action in /usr/local/bin/admin.pl, or a hard link attack in (2) chmod or (3) a certain cp command.

    Source:Tim Brown
    Published:19 Feb 2010
    7.8
    High

    CVE-2009-4645

    Last Modified: 3 Jun 2014

    Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Source:Tim Brown
    Published:19 Feb 2010
    10
    Critical

    CVE-2009-4637

    Last Modified: 8 May 2014

    FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.

    Source:Will Dormann
    Published:10 Feb 2010
    7.5
    High

    CVE-2009-4628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.

    Source:NoGe
    Published:18 Jan 2010
    5
    Medium

    CVE-2009-4627

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the p_filename parameter, a different issue than CVE-2009-4614.

    Source:GoLd_M
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4626

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the conf[lang] parameter.

    Source:CoBRa_21
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4625

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php.

    Source:jdc
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4624

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843.

    Source:Mr.SQL
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4623

    Last Modified: 26 Mar 2014

    Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the ACS_path parameter to (1) index.php and (2) admin.php in advanced_comment_system/. NOTE: this might only be a vulnerability when the administrator has not followed installation instructions in install.php. NOTE: this might be the same as CVE-2020-35598.

    Source:Kurd-Team
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4622

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-0572.

    Source:EA Ngel
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4621

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.

    Source:ZhaoHuAn
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4620

    Last Modified: 19 Feb 2017

    SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

    Source:Chip d3 bi0s
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4618

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the sitetext_id parameter to (1) aboutus.php and (2) faq.php.

    Source:Mr.SQL
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4617

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php.

    Source:Mr.SQL
    Published:18 Jan 2010
    4.3
    Medium

    CVE-2009-4616

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.

    Source:Mr.SQL
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4615

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQL commands via the link_id parameter in a show_review action.

    Source:Mr.SQL
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4614

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Moa Gallery 1.2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the MOA_PATH parameter to (1) _error_funcs.php, (2) _integrity_funcs.php, (3) _template_component_admin.php, (4) _template_component_gallery.php, (5) _template_parser.php, (6) mod_gallery_funcs.php, (7) mod_image_funcs.php, (8) mod_tag_funcs.php, (9) mod_tag_view.php, (10) mod_upgrade_funcs.php, (11) mod_user_funcs.php, (12) page_admin.php, (13) page_gallery_add.php, (14) page_gallery_view.php, (15) page_image_add.php, (16) page_image_view_full.php, (17) page_login.php, and (18) page_sitemap.php in sources/.

    Source:cr4wl3r
    Published:18 Jan 2010
    7.5
    High

    CVE-2009-4613

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:AnTi SeCuRe
    Published:14 Jan 2010
    4.3
    Medium

    CVE-2009-4612

    Last Modified: 29 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

    Source:aScii
    Published:25 Oct 2009
    4.3
    Medium

    CVE-2009-4610

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the Session Dump Servlet under session/.

    Source:Antonion Parata
    Published:25 Oct 2009
    7.2
    High

    CVE-2009-4607

    Last Modified: 23 Apr 2026

    The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the CLI user and without sufficient restriction on shell escapes, which allows local users to gain privileges using the "!" character within less to access a privileged shell.

    Source:trompele
    Published:13 Jan 2010
    7.2
    High

    CVE-2009-4606

    Last Modified: 27 Jun 2010

    South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.

    Source:Trancer
    Published:13 Jan 2010
    7.5
    High

    CVE-2009-4604

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mamboleto.php in the Fernando Soares Mamboleto (com_mamboleto) component 2.0 RC3 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Don Tukulesto
    Published:12 Jan 2010
    4.3
    Medium

    CVE-2009-4601

    Last Modified: 17 May 2014

    Cross-site scripting (XSS) vulnerability in basic_search_result.php in Zeeways ZeeJobsite 3x allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Source:bi0
    Published:12 Jan 2010
    7.5
    High

    CVE-2009-4600

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information.

    Source:AnTi SeCuRe
    Published:12 Jan 2010
    7.5
    High

    CVE-2009-4599

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the md parameter in an employer view_company action to index.php or (2) the oi parameter in an employer view_job action to index.php.

    Source:kaMtiEz
    Published:12 Jan 2010
    7.5
    High

    CVE-2009-4598

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action to index.php.

    Source:kaMtiEz
    Published:12 Jan 2010
    7.5
    High

    CVE-2009-4597

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a users details action, and allow remote attackers to execute arbitrary SQL commands via the (2) user (username) and (3) pass (password) parameters. NOTE: some of these details are obtained from third party information.

    Source:mr_me
    Published:12 Jan 2010
    4.3
    Medium

    CVE-2009-4596

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary web script or HTML via the sup_id parameter in a suppliers details action.

    Source:mr_me
    Published:12 Jan 2010
    6
    Medium

    CVE-2009-4595

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the sup_id parameter in a suppliers details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:mr_me
    Published:12 Jan 2010
    9.3
    Critical

    CVE-2009-4588

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a different vulnerability than CVE-2009-2386. NOTE: some of these details are obtained from third party information.

    Source:shinnai
    Published:7 Jan 2010
    5
    Medium

    CVE-2009-4587

    Last Modified: 23 Apr 2026

    Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.

    Source:Usman Saeed
    Published:7 Jan 2010
    5
    Medium

    CVE-2009-4585

    Last Modified: 23 Apr 2026

    UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/db.mdb.

    Source:LionTurk
    Published:6 Jan 2010
    7.5
    High

    CVE-2009-4583

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a grouplist action to index.php.

    Source:ViRuSMaN
    Published:6 Jan 2010
    7.5
    High

    CVE-2009-4582

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Palyo34
    Published:6 Jan 2010
    9.8
    Critical

    CVE-2009-4581

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter.

    Source:cr4wl3r
    Published:6 Jan 2010
    4.3
    Medium

    CVE-2009-4578

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.

    Source:Pyske
    Published:6 Jan 2010
    7.5
    High

    CVE-2009-4576

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to index.php.

    Source:FL0RiX
    Published:6 Jan 2010
    4.3
    Medium

    CVE-2009-4575

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_sira parameter in a sirala action to index.php.

    Source:Pyske
    Published:6 Jan 2010
    7.5
    High

    CVE-2009-4574

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in country_escorts.php in I-Escorts Directory Script allows remote attackers to execute arbitrary SQL commands via the country_id parameter.

    Source:R3d-D3V!L
    Published:6 Jan 2010
    7.5
    High

    CVE-2009-4571

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL commands via the (1) module_id parameter in an admin/function_list action, the (2) vendor_id parameter in a vendor/vendor_form action, the (3) module_id parameter in an admin/module_form action, the (4) user_id parameter in an admin/user_form action, the (5) vendor_category_id parameter in a vendor/vendor_category_form action, the (6) user_id parameter in a store/user_form action, the (7) payment_method_id parameter in a store/payment_method_form action, the (8) tax_rate_id parameter in a tax/tax_form action, or the (9) category parameter in a shop/browse action. NOTE: the product_id vector is already covered by CVE-2008-0681.

    Source:Andrea Fabrizi
    Published:5 Jan 2010
    7.5
    High

    CVE-2009-4569

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.

    Source:SadHaCkEr
    Published:5 Jan 2010
    3.5
    Low

    CVE-2009-4567

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in editprofile.php in Viscacha 0.8 Gold allow remote authenticated users to inject arbitrary web script or HTML via the (1) skype, (2) yahoo, (3) aol, (4) msn, or (5) jabber parameter in a profile2 action. NOTE: some of these details are obtained from third party information.

    Source:mr_me
    Published:5 Jan 2010
    7.5
    High

    CVE-2009-4566

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:petros
    Published:4 Jan 2010
    6.8
    Medium

    CVE-2009-4564

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.

    Source:petros
    Published:4 Jan 2010
    4.3
    Medium

    CVE-2009-4563

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_2 parameters in a saveoptions action.

    Source:petros
    Published:4 Jan 2010
    4.3
    Medium

    CVE-2009-4562

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the from parameter.

    Source:petros
    Published:4 Jan 2010
    6.8
    Medium

    CVE-2009-4561

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:ka0x
    Published:4 Jan 2010
    7.5
    High

    CVE-2009-4560

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Source:Arka69
    Published:4 Jan 2010